<?xml version="1.0" encoding="utf-8"?>
<glsa id="200503-06">
<title>BidWatcher: Format string vulnerability</title>
BidWatcher is vulnerable to a format string vulnerability, potentially
allowing arbitrary code execution.
<product type="ebuild">bidwatcher</product>
<announced>March 03, 2005</announced>
<revised>March 03, 2005: 01</revised>
<package name="net-misc/bidwatcher" auto="yes" arch="*">
<unaffected range="ge">1.3.17</unaffected>
<vulnerable range="lt">1.3.17</vulnerable>
BidWatcher is a free auction tool for eBay users to keep track of
their auctions.
Ulf Harnhammar discovered a format string vulnerability in
<impact type="normal">
Remote attackers can potentially exploit this vulnerability by
sending specially crafted responses via an eBay HTTP server or a
man-in-the-middle attack to execute arbitrary malicious code.
There is no known workaround at this time.
All BidWatcher users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=net-misc/bidwatcher-1.13.17&quot;</code>
<uri link="">CAN-2005-0158</uri>
<metadata tag="requester" timestamp="Tue, 1 Mar 2005 08:44:34 +0000">
<metadata tag="bugReady" timestamp="Tue, 1 Mar 2005 15:30:43 +0000">
<metadata tag="submitter" timestamp="Wed, 2 Mar 2005 20:11:39 +0000">